
WP MtG-Helper Security & Risk Analysis
wordpress.org/plugins/wp-mtg-helperThe goal of this plugin is to help you writing articels about Magic: the Gathering like tournament reports or draft walkthroughs and reducing the time …
Is WP MtG-Helper Safe to Use in 2026?
Generally Safe
Score 85/100WP MtG-Helper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-mtg-helper v1.2.7 plugin exhibits a mixed security posture. On the positive side, it has no known vulnerabilities in its history and demonstrates good use of nonce and capability checks, indicating an awareness of security principles. The absence of critical or high-severity taint flows and dangerous functions further contributes to a seemingly robust internal code structure regarding common exploit vectors.
However, significant concerns arise from the static analysis. The plugin executes 8 SQL queries, none of which utilize prepared statements. This is a major security risk, as it opens the door to SQL injection vulnerabilities if any of the data feeding these queries originates from user input without proper sanitization. Furthermore, out of 114 output operations, a concerning 0% are properly escaped. This lack of output escaping is a critical flaw that could lead to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website.
While the plugin has no recorded vulnerabilities, the identified static analysis issues represent significant potential weaknesses. The absence of past CVEs might indicate diligent patching by developers or simply that the plugin hasn't been a target, but it does not negate the inherent risks in the current codebase. The plugin's strength lies in its entry point management and use of checks, but its weakness is in fundamental data handling and output sanitization.
Key Concerns
- SQL queries without prepared statements
- Output escaping not properly implemented
WP MtG-Helper Security Vulnerabilities
WP MtG-Helper Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP MtG-Helper Attack Surface
Shortcodes 2
WordPress Hooks 18
Maintenance & Trust
WP MtG-Helper Maintenance & Trust
Maintenance Signals
Community Trust
WP MtG-Helper Alternatives
Magic the Gathering Card Tooltips
magic-the-gathering-card-tooltips
Easily transform Magic the Gathering card names into links that show the card image in a tooltip when hovering over them. You can also quickly create …
MTGPulse deckbox embedding tool
mtgpulse-magic-the-gathering-deckbox-plugin
Facilitates embedding of MTGPulse.com deckboxes on your word press site
MtG-Tutor.de CardLinker
mtg-tutorde-cardlinker
This plugin provides some shortcode to easily link MtG Cards and Decks! - Ein Plugin mit dem man ganz leicht MtG Karten und Decks verlinken kann!
ReachDeck Toolbar
browsealoud
Websites made more accessible with easy speech, reading and translation tools.
Mana Symbols
mana-symbols
Mana Symbols replaces shortcodes with Magic: The Gathering mana symbols.
WP MtG-Helper Developer Profile
1 plugin · 10 total installs
How We Detect WP MtG-Helper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-mtg-helper/js/mtgh.js/wp-content/plugins/wp-mtg-helper/js/jquery.dimensions.min.js/wp-content/plugins/wp-mtg-helper/css/mtgh.css/wp-content/plugins/wp-mtg-helper/js/mtgh.js/wp-content/plugins/wp-mtg-helper/js/jquery.dimensions.min.jswp-mtg-helper/js/mtgh.js?ver=wp-mtg-helper/js/jquery.dimensions.min.js?ver=